Location-Aware Two-Factor Authentication Using GPS Signals
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional two-factor authentication methods are susceptible to security concerns and user experience disruptions, particularly in web-based applications, as they often rely on time-sensitive codes or hardware tokens that can cause delays and are vulnerable to location circumvention.
Innovation Solution
A location-aware two-factor authentication system using a device with a localization signal receiver and a client device, where the system receives and measures localization signals to determine the device's location, allowing or denying authentication based on this information, and transmits encrypted requests to a web service for verification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If time-sensitive codes are sent via email or SMS for two-factor authentication, then security is improved, but user experience deteriorates due to delays and interaction disruption
Solution Approach 1:
The patent introduces a hardware token as an intermediary device that generates and displays authentication codes locally without requiring network communication during the authentication process. This mediator eliminates the delay caused by email/SMS delivery while maintaining security through cryptographic code generation, thus resolving the contradiction between security and user experience.
2Device complexity
If traditional two-factor authentication without location awareness is used, then device complexity is reduced, but security deteriorates due to vulnerability to location circumvention
Solution Approach 1:
The patent implements location determination as a preliminary action before authentication code verification. The system pre-establishes geographic boundaries and determines the user's location in advance, then uses this location information as an additional security factor. This preliminary location check enhances security against location circumvention without significantly increasing device complexity, as the location determination leverages existing GPS capabilities.
3Reliability
If location determination is added to two-factor authentication, then security is improved by preventing unauthorized access, but device complexity increases
Solution Approach 1:
The patent leverages the universal GPS capability already present in modern smartphones to perform location determination. By utilizing this existing multi-functional feature of mobile devices, the system adds location-based security without requiring specialized hardware or significantly increasing device complexity. The GPS receiver serves multiple purposes including navigation and now authentication, demonstrating the universality principle.
Data Source
AI summary
A system and method that extend the protections provided by the existing state-of-the-art to provide location-aware two-factor authentication for authenticating users of computer systems. There are many potential use cases where location-aware two-factor authentication could be of value. For instance, for purposes of access to critical business documentation, such as intellectual property, financial data, sales data for publicly traded companies, and personal medical information are all heavily protected information artifacts in most organizations. Providing controls to insure this information is only accessed in secure, trusted locations could greatly reduce the potential of inappropriate information access.


